hacker-news · Crawled Jul 13, 2026

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

2 IoCs 4 CVEs
Read original article ↗

AI Summary

The U.S. CISA has added two critical vulnerabilities in Joomla extensions iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog due to active zero-day exploitation. CVE-2026-48939 and CVE-2026-56291, both rated 10.0 CVSS, allow unauthenticated remote code execution via arbitrary file upload. These flaws are being exploited in automated attacks to deploy web shells on vulnerable Joomla sites. Australia's ACSC has also warned of a global campaign exploiting similar CMS vulnerabilities.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 2 extracted

Type Value Detail
Filename images/icagenda/frontend/attachments/ Details →
Filename images/baforms/uploads Details →

MITRE ATT&CK TTPs 15 techniques